Location-Aware Two-Factor Authentication Using GPS Signals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional two-factor authentication methods are susceptible to security concerns and user experience disruptions, particularly in web-based applications, as they often rely on time-sensitive codes or hardware tokens that can cause delays and are vulnerable to location circumvention.

Innovation Solution

A location-aware two-factor authentication system using a device with a localization signal receiver and a client device, where the system receives and measures localization signals to determine the device's location, allowing or denying authentication based on this information, and transmits encrypted requests to a web service for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If time-sensitive codes are sent via email or SMS for two-factor authentication, then security is improved, but user experience deteriorates due to delays and interaction disruption

Engineering Contradiction:
ImprovesecurityVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a hardware token as an intermediary device that generates and displays authentication codes locally without requiring network communication during the authentication process. This mediator eliminates the delay caused by email/SMS delivery while maintaining security through cryptographic code generation, thus resolving the contradiction between security and user experience.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If traditional two-factor authentication without location awareness is used, then device complexity is reduced, but security deteriorates due to vulnerability to location circumvention

Engineering Contradiction:
Improvesystem simplicityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements location determination as a preliminary action before authentication code verification. The system pre-establishes geographic boundaries and determines the user's location in advance, then uses this location information as an additional security factor. This preliminary location check enhances security against location circumvention without significantly increasing device complexity, as the location determination leverages existing GPS capabilities.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If location determination is added to two-factor authentication, then security is improved by preventing unauthorized access, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal GPS capability already present in modern smartphones to perform location determination. By utilizing this existing multi-functional feature of mobile devices, the system adds location-based security without requiring specialized hardware or significantly increasing device complexity. The GPS receiver serves multiple purposes including navigation and now authentication, demonstrating the universality principle.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11196736B2Systems and methods for location-aware two-factor authentication
Publication Date: 2021.12.07 FUJIFILM BUSINESS INNOVATION CORP
  • US11196736B2 patent drawing
  • US11196736B2 patent drawing
  • US11196736B2 patent drawing

AI summary

A system and method that extend the protections provided by the existing state-of-the-art to provide location-aware two-factor authentication for authenticating users of computer systems. There are many potential use cases where location-aware two-factor authentication could be of value. For instance, for purposes of access to critical business documentation, such as intellectual property, financial data, sales data for publicly traded companies, and personal medical information are all heavily protected information artifacts in most organizations. Providing controls to insure this information is only accessed in secure, trusted locations could greatly reduce the potential of inappropriate information access.